AWS Advanced Networking - Free 8-Hour Full Course Companion (VPC, NAT Gateway, Bastion, ALB, NLB, WAF, VPC Peering, Transit Gateway, VPC Endpoints and PrivateLink, Route 53, ACM) with Timestamps and the ANS-C01 Exam Facts


This is the companion page to my free AWS Advanced Networking full course - eight hours in which one lab environment is built layer by layer, from an empty VPC to a multi-VPC, multi-account network with load balancers, a firewall, private connectivity, DNS and TLS. Every chapter of the video has a detailed written version in the AWS step-by-step series on this site, each re-verified against the current AWS documentation in October 2026. Use the video to watch the build, use the posts for the exact console steps, CLI commands, limits, prices and the "common errors" sections that the video could not fit.

The course was recorded with the AWS Certified Advanced Networking - Specialty (ANS-C01) exam in mind. One important update: AWS has announced that ANS-C01 is retiring, with 31 December 2026 the last day to sit it (certification page). If the certificate is your goal, plan the exam date accordingly; if the knowledge is your goal, nothing changes - this is the networking every AWS engineer needs regardless of the exam.

Table of Content

  1. How the course is built
  2. Chapter 1 - VPC essentials (0:01:06)
  3. Chapter 2 - NAT Gateway (0:36:00)
  4. Chapter 3 - Bastion host (0:59:36)
  5. Chapter 4 - Application Load Balancer (1:31:00)
  6. Chapter 5 - Network Load Balancer (1:57:00)
  7. Chapter 6 - Web Application Firewall (2:47:00)
  8. Chapter 7 - VPC peering (3:15:00)
  9. Chapter 8 - Transit Gateway (3:39:00)
  10. Chapters 9 and 10 - VPC endpoints and PrivateLink (4:12:00 and 4:45:00)
  11. Chapter 11 - Route 53 (5:57:00)
  12. Chapter 12 - SSL/TLS with ACM (7:13:00)
  13. The ANS-C01 exam - facts, domains, retirement
  14. What the course does not cover
  15. Study path



1. How the course is built

AWS Advanced Networking course map - eleven chapters over eight hours, each mapped to a post in the AWS step-by-step series

The eight hours follow one architecture -

  1. Build the network (0:01 - 1:31) - a VPC with public and private subnets, Internet Gateway, route tables, a NAT Gateway, a bastion host.
  2. Expose and protect it (1:31 - 3:15) - an Application Load Balancer, a Network Load Balancer, and WAF in front.
  3. Connect networks (3:15 - 5:57) - VPC peering, Transit Gateway, VPC endpoints and PrivateLink.
  4. Names and certificates (5:57 - 8:00) - Route 53 and ACM.

Each layer uses the previous one, so watch in order. You need an AWS account (the Free plan covers everything except a few dollars of NAT Gateway and load balancer hours - delete them when you stop for the day) and an IAM user or Identity Center login (Part-1).


2. Chapter 1 - VPC essentials (0:01:06)

Builds - a VPC 10.0.0.0/16, two public and two private subnets across two AZs, an Internet Gateway, public and private route tables, and the first EC2 instances to prove which subnet can reach what. The video spends the first half hour here because every later chapter depends on getting this right.

Key ideas - a subnet is public or private only because of its route table; CIDR planning; the five reserved addresses per subnet; 0.0.0.0/0 → igw.

Written version - Part-5: VPC with public and private subnets, Internet Gateway, NAT Gateway and route tables. Background if the vocabulary is new: what is a VPC and a subnet and what is CIDR.



3. Chapter 2 - NAT Gateway (0:36:00)

Builds - a NAT Gateway with an Elastic IP in a public subnet and the private route table pointing 0.0.0.0/0 at it; a private instance runs apt update and curl checkip.amazonaws.com shows the NAT's address.

Key ideas - PAT, outbound-only, one per AZ for HA, the per-hour and per-GB cost, and the free S3/DynamoDB gateway endpoints that keep traffic off it.

Written version - Part-14: NAT Gateway deep dive (limits, metrics, cost optimisation, troubleshooting) and the concept post what is NAT.


4. Chapter 3 - Bastion host (0:59:36)

Builds - a hardened EC2 instance in a public subnet as the only SSH entry point, with a security group that allows port 22 from your IP and private instances that allow SSH only from the bastion's security group; SSH agent forwarding to hop through.

Key ideas - security group references instead of CIDRs, key pairs, and the modern alternatives that remove the bastion entirely - EC2 Instance Connect Endpoint and Session Manager.

Written version - the bastion and app-server test in Part-5, step 7, and the connection methods in Part-4: launch an EC2 instance.


5. Chapter 4 - Application Load Balancer (1:31:00)

Builds - a target group with web instances, an internet-facing ALB across the two public subnets, an HTTP listener, and a test that shows requests alternating between instances; then listener rules by path.

Key ideas - layer 7, listeners and rules, target groups and health checks, cross-zone load balancing, and how an Auto Scaling group registers targets automatically.

Written version - the ALB build inside Part-10: EC2 Auto Scaling, and the Terraform version in setting up an ALB and SSL.



6. Chapter 5 - Network Load Balancer (1:57:00)

Builds - a target group and an NLB with static IPs per AZ, a TCP listener, and the comparison with the ALB - what the NLB does not see, and what it does better.

Key ideas - layer 4, static and Elastic IPs, client IP preservation and its effect on target security groups, cross-zone off by default, security groups only at creation, NLB in front of an ALB.

Written version - Part-18: Network Load Balancer, and ALB vs NLB.


7. Chapter 6 - Web Application Firewall (2:47:00)

Builds - a web ACL associated with the ALB, AWS managed rule groups (Core rule set, SQL injection, known bad inputs), a rate-based rule and a geo rule, then a SQL-injection curl that returns 403.

Key ideas - rules in priority order, Allow/Block/Count/CAPTCHA, WCUs, tuning in Count mode with sampled requests, logging, the $5 + $1 + $0.60 pricing.

Written version - Part-11: AWS WAF.


8. Chapter 7 - VPC peering (3:15:00)

Builds - a second VPC with a non-overlapping CIDR, a peering request and acceptance, routes in both VPCs, security group rules, and a ping across.

Key ideas - no overlapping CIDRs, not transitive, no edge-to-edge routing, DNS resolution over peering, cross-account and cross-region, free apart from data transfer.

Written version - Part-12: VPC peering.


9. Chapter 8 - Transit Gateway (3:39:00)

Builds - a Transit Gateway, VPC attachments for three VPCs with a subnet per AZ, routes in each VPC towards the TGW, the TGW route table with associations and propagations, and the isolation pattern where two spokes reach shared services but not each other.

Key ideas - hub-and-spoke, two layers of routing, associations vs propagations, VPN and Direct Connect attachments, peering between TGWs, RAM sharing, attachment-hour pricing.

Written version - Part-13: Transit Gateway.



Builds - the consumer side first: a gateway endpoint for S3 and interface endpoints for Systems Manager so a private instance with no NAT reaches S3 and is managed by Session Manager; then the provider side: an application behind an internal NLB published as an endpoint service, a consumer VPC with an interface endpoint to it, acceptance, and a private DNS name.

Key ideas - gateway vs interface endpoints, private DNS, endpoint policies and aws:sourceVpce, the ECR/SSM endpoint sets, cost vs NAT; endpoint services, allowed principals, acceptance, domain verification, proxy protocol v2, cross-region.

Written versions - Part-19: VPC endpoints and Part-20: PrivateLink endpoint service.


11. Chapter 11 - Route 53 (5:57:00)

Builds - a public hosted zone, moving a domain's name servers to Route 53, alias records to the ALB, and the routing policies - weighted, latency, failover with health checks, geolocation - plus a private hosted zone for internal names.

Key ideas - alias vs CNAME, TTLs, health checks and DNS failover, split-horizon DNS, Resolver endpoints, pricing per zone and per million queries.

Written version - Part-15: Route 53.


12. Chapter 12 - SSL/TLS with ACM (7:13:00)

Builds - a public certificate for the domain and its wildcard, DNS validation with one click in Route 53, an HTTPS listener on the ALB with a modern TLS policy, HTTP-to-HTTPS redirect, and the same certificate on CloudFront (requested in us-east-1).

Key ideas - free certificates with the private key inside AWS, the region rules, automatic renewal via the validation CNAME - and two changes since the video: certificates now last 198 days, and ACM can issue exportable certificates for servers outside AWS.

Written version - Part-16: AWS Certificate Manager.


13. The ANS-C01 exam - facts, domains, retirement

From the official certification page -

LevelSpecialty
Length170 minutes
Questions65, multiple choice and multiple response
Cost300 USD
DeliveryPearson VUE test centre or online proctored
LanguagesEnglish, Japanese, Korean, Simplified Chinese
Recommended experience5+ years of networking, 2+ years of cloud and hybrid networking
Retirementthe last day to take ANS-C01 is 31 December 2026

The exam guide splits the content into four domains - Network Design, Network Implementation, Network Management and Operation, and Network Security, Compliance and Governance. The course covers the implementation and operation of every service in those domains; the exam adds depth on hybrid connectivity (Direct Connect, Site-to-Site VPN, BGP), Cloud WAN, Global Accelerator, Network Firewall, Gateway Load Balancer, IPv6, VPC Flow Logs and Traffic Mirroring and Reachability Analyzer - the topics of section 14. Being a specialty exam, the questions are scenario-based ("a company has overlapping CIDRs and must connect ... which option has the least operational overhead") rather than "what does this flag do".



14. What the course does not cover

The honest list, so you can fill the gaps from the AWS documentation before the exam -

  1. AWS Direct Connect - dedicated and hosted connections, virtual interfaces (private, public, transit), Direct Connect gateways, LAG, BGP communities, resiliency models.
  2. Site-to-Site VPN - customer gateways, tunnels, BGP vs static, ECMP over Transit Gateway, accelerated VPN, Client VPN.
  3. AWS Cloud WAN and Network Manager - the global, policy-driven successor to many-TGW designs.
  4. Global Accelerator - anycast static IPs in front of regional ALBs/NLBs.
  5. AWS Network Firewall and Gateway Load Balancer - inspection VPCs, centralised egress with firewalls.
  6. IPv6 - dual-stack VPCs, egress-only Internet Gateways, NAT64/DNS64, IPv6-only subnets.
  7. Observability - VPC Flow Logs, Traffic Mirroring, Reachability Analyzer, Network Access Analyzer, CloudWatch network metrics.
  8. Route 53 Resolver in depth - inbound/outbound endpoints, forwarding rules, DNS Firewall, DNSSEC.
  9. VPC Lattice and the newer PrivateLink resource and service-network endpoints.
  10. Networking for containers and Kubernetes - EKS VPC CNI, ECS networking modes.

Flow logs, security groups, launch templates and EBS have their own videos in the series and posts are on the way; Azure's equivalents are in my Azure networking videos.


15. Study path

  1. Watch the eight hours in four sittings, one part per sitting, and build along in your own account; destroy NAT Gateways, load balancers and Transit Gateway attachments at the end of each sitting (they bill per hour).
  2. Read the matching post after each chapter for the limits, prices, CLI commands and errors - that is where exam-style detail lives.
  3. Fill the gaps from section 14 with the AWS documentation - Direct Connect and Site-to-Site VPN deserve a weekend each.
  4. Practise the three recurring exam patterns: overlapping CIDRs (PrivateLink or private NAT), centralised egress and inspection (Transit Gateway plus Network Firewall), and hybrid DNS (Resolver endpoints).
  5. Book before the retirement date if you want ANS-C01 on your profile.

The whole written series is listed below, starting with Part-1: IAM, and the AWS networking product pages are at aws.amazon.com/products/networking.


More videos on this topic - the course update video, the dynamic routing demo (AWS and Google Cloud site-to-site VPN with high-availability VPN), and default routing vs static routing -




AWS step by step series -

  1. Part-1 : AWS IAM user - create a user, group, policy, access keys and MFA
  2. Part-2 : AWS Organizations - multi-account setup, OUs and SCPs
  3. Part-3 : AWS assume IAM role - trust policy, switch role in console and CLI
  4. Part-4 : How to launch an EC2 instance - key pair, security group, SSH
  5. Part-5 : AWS VPC - public and private subnets, Internet Gateway, NAT Gateway, route tables
  6. Part-8 : EC2 launch template - versions, default version, source template, SSM parameter AMI
  7. Part-10 : EC2 Auto Scaling - launch template, Auto Scaling group, target tracking, ALB
  8. Part-11 : AWS WAF - web ACL, managed rules, rate limiting, geo blocking
  9. Part-12 : AWS VPC Peering - connect two VPCs, routes, security groups, DNS
  10. Part-13 : AWS Transit Gateway - hub-and-spoke for many VPCs and on-premises
  11. Part-14 : AWS NAT Gateway deep dive - public vs private, limits, cost, troubleshooting
  12. Part-15 : Amazon Route 53 - hosted zones, records, alias, routing policies, health checks
  13. Part-16 : AWS security groups - inbound and outbound rules, stateful, referencing, quotas
  14. Part-16 : AWS Certificate Manager - free TLS certificates for ALB, CloudFront and API Gateway
  15. Part-17 : AWS Lambda - function URLs, environment variables and layers
  16. Part-18 : Network Load Balancer - setup, and ALB vs NLB
  17. Part-19 : VPC endpoints - gateway and interface endpoints (PrivateLink) instead of NAT
  18. Part-20 : AWS PrivateLink - publish your own service with an endpoint service and NLB
  19. Part-20 : Amazon EBS volumes - types, attach, mount, resize, snapshots, encryption
  20. Part-21 : VPC Flow Logs - CloudWatch Logs, S3, record format, Logs Insights, Athena
  21. Part-21 : EC2 Spot Instances - pricing, interruptions, mixed instances groups
  22. Part-24 : AWS Control Tower - landing zone, controls, Account Factory, Identity Center

Networking fundamentals -

  1. What is a VPC and a subnet? AWS networking in five minutes
  2. What is CIDR? Calculate IP ranges for VPCs and subnets
  3. What is NAT? Static NAT, dynamic NAT and PAT explained

More AWS guides -

  1. What is AWS CloudFormation? Templates, stacks, change sets, drift, StackSets
  2. Learn AWS S3 - the complete course
  3. AWS API Gateway - REST API with Lambda, authorizers, Terraform
  4. AWS Advanced Networking Specialty (ANS-C01) - course companion
  5. AWS ECS and Fargate - how to deploy a Docker container
  6. AWS S3 - how to host a static website
  7. Terraform create EC2 instance on AWS
  8. Terraform AWS IAM - users, roles and policies
  9. Terraform and AWS multi-account setup
  10. Terraform - setting up an ALB and SSL

Posts in this series